figma-code-connect

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves a legitimate developer productivity purpose, facilitating the creation of configuration files for Figma Code Connect. It follows standard patterns for code generation and component discovery.
  • [EXTERNAL_DOWNLOADS]: The documentation references official Figma developer tools, including the @figma/code-connect package and CLI. These are well-known resources provided by an established service provider for their own ecosystem and do not represent a security risk.
  • [COMMAND_EXECUTION]: The skill mentions standard CLI commands for publishing and managing Code Connect files (npx figma connect publish). These are presented as instructional examples for the user's manual execution and are consistent with the tool's primary purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Figma URLs and component context provided by a Figma MCP server. While this constitutes an ingestion of external data, the skill includes explicit validation steps, requiring the agent to compare design properties against local code interfaces and verify the generated output before completion. The severity is low as this behavior is inherent to the functionality of a design-to-code tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — figma-code-connect